Apparatus and method for password-based distributed authentication
Abstract
Disclosed herein is an apparatus and method for password-based distributed authentication. The apparatus includes memory in which at least one program is recorded and a processor for executing the program. The program may perform at least one of registering a password input by a user in a service membership sign-up procedure in multiple servers in a distributed manner based on multi-party computation, authenticating a password input by the user in a login procedure based on multi-party computation with the multiple servers, or acquiring resources of a service requested by the authenticated user, or a combination thereof.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus for password-based distributed authentication, comprising:
memory in which at least one program is recorded; and a processor for executing the program, wherein the program performs at least one of registering a password input by a user in a service membership sign-up procedure in multiple servers in a distributed manner based on multi-party computation, authenticating a password input by the user in a login procedure based on multi-party computation with the multiple servers, or acquiring a resource of a service requested by the authenticated user, or a combination thereof.
2 . The apparatus of claim 1 , wherein, when registering the password, the program performs
receiving an identifier and the password from the user who requests signing up for a membership, converting the received password into a password verification value, generating a secret-sharing polynomial using the password verification value, generating multiple password verification fragment values using the secret-sharing polynomial and IDs of the multiple servers, and distributing the password verification fragment values to corresponding ones of the multiple servers.
3 . The apparatus of claim 2 , wherein converting the received password comprises converting the received password into the password verification value using a salt or a hash.
4 . The apparatus of claim 2 , wherein generating the secret-sharing polynomial comprises generating the secret-sharing polynomial using a Shamir's secret sharing method.
5 . The apparatus of claim 1 , wherein, when authenticating the password, the program performs
generating a token generation key when an identifier and the password are input by the user, converting the password input by the user into a password verification value, restoring a password verification comparison value, checking whether the restored password verification comparison value matches the password verification value, generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value, and storing the generated token.
6 . The apparatus of claim 5 , wherein
when restoring the password verification comparison value, the program restores the password verification comparison value based on password verification fragment values of t servers, among N servers across which the password verification fragment values are distributed, and the password verification comparison value is calculated as a sum of Lagrange basis polynomials multiplied by the respective password verification fragment values.
7 . The apparatus of claim 5 , wherein the token includes a token signature and token data.
8 . The apparatus of claim 7 , wherein the token data includes at least one of a user ID, a token serial number, service access authority information, a token issuance date and time, or a token expiration date and time, or a combination thereof.
9 . The apparatus of claim 5 , wherein the token key is generated based on a sum of token generation keys initially generated by a user terminal and t servers.
10 . The apparatus of claim 1 , wherein, when acquiring the resource, the program performs
retrieving whether a token for the requested service is present, transferring the retrieved token to a server providing the requested service, and receiving the resource from the server when the token is verified.
11 . An apparatus for password-based distributed authentication, comprising:
memory in which at least one program is recorded; and a processor for executing the program, wherein the program performs at least one of registering password verification fragment values generated through multi-party computation with one or more additional servers based on a password input by a user through a user terminal in a service membership sign-up procedure, authenticating a password input by the user in a login procedure based on multi-party computation using the password verification fragment values registered in the one or more additional servers in a distributed manner, or providing a resource of a service requested from the user terminal based on token verification, or a combination thereof.
12 . The apparatus of claim 11 , wherein, when authenticating the password, the program performs
reading the password verification fragment values corresponding to an identifier of the user and generating a token generation key, converting the password input by the user into a password verification value, restoring a password verification comparison value from the password verification fragment values registered in a distributed manner through multi-party computation with the one or more additional servers, checking whether the restored password verification comparison value matches the password verification value, generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value, and storing the generated token key.
13 . The apparatus of claim 12 , wherein the token key is generated based on a sum of token generation keys initially generated by the user terminal and t servers.
14 . The apparatus of claim 11 , wherein, when providing the resource, the program performs
receiving a service request and a token from the user terminal, retrieving a token key corresponding to the token, verifying the token using the retrieved token key, and providing the resource when the token is verified.
15 . The apparatus of claim 14 , wherein, when verifying the token, the program performs
generating a token signature using the retrieved token key and token data included in the token, and checking whether the generated token signature matches a token signature included in the token.
16 . A method for password-based distributed authentication, comprising:
receiving an identifier and a password from a user who requests signing up for a membership; converting the received password into a password verification value; generating a secret-sharing polynomial using the password verification value; generating multiple password verification fragment values using the secret-sharing polynomial and IDs of multiple servers; and distributing the password verification fragment values to corresponding ones of the multiple servers.
17 . The method of claim 16 , further comprising:
generating a token generation key when an identifier and a password are input by the user; converting the password input by the user into a password verification value; restoring a password verification comparison value; checking whether the restored password verification comparison value matches the password verification value; generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value; and storing the generated token.
18 . The method of claim 17 , wherein
restoring the password verification comparison value comprises restoring the password verification comparison value based on password verification fragment values of t servers, among N servers across which the password verification fragment values are distributed, and the password verification comparison value is calculated as a sum of Lagrange basis polynomials multiplied by the respective password verification fragment values.
19 . The method of claim 18 , wherein the token key is generated based on a sum of token generation keys initially generated by a user terminal and the t servers.
20 . The method of claim 16 , further comprising:
acquiring a resource of a service requested by the user, wherein: acquiring the resource includes retrieving whether a token for the requested service is present, transferring the retrieved token to a server providing the requested service, and receiving the resource from the server when the token is verified, and the token includes a token signature and token data and is verified depending on whether the token signature included in the transferred token matches a token signature generated by the server using a token key and the token data.Join the waitlist — get patent alerts
Track US2025219836A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.